On the weekend of 7 and 8 February 2026, Odido discovered a breach in which data of 6.2 million customer accounts was stolen: name, address, e-mail address, phone number, date of birth and identity document numbers. Passwords and payment details were not affected. The attackers posed as IT staff and obtained login credentials from customer service employees. When Odido refused to pay a ransom, the ShinyHunters collective published part of the data. Large or small: the question is not whether an incident will hit you, but when. The difference lies in preparation.
Social engineering — an attack that exploits people rather than a technical flaw: the attacker creates trust or urgency to obtain access, data or money. At Odido it was an impersonated IT colleague.
What Odido teaches us
The breach did not start with advanced malware, but with a call or e-mail that was credible enough. One set of credentials then proved sufficient for access to a system with millions of customer records. Two lessons: human behaviour is the first line of defence, and access to sensitive data should never depend on a single password. At Qteco we therefore put one thing first: get the basics right. That starts with four honest questions.
1 · Is the password policy really secure enough?
If employees still use reused or simple passwords, the answer is no. Require unique passwords and always combine them with two-step verification (MFA), preferably phishing-resistant with passkeys. Without that extra layer, one stolen password is often enough for full access.
2 · Are the main communication channels protected?
E-mail and phone remain the largest attack routes. Choose AI-driven e-mail security that recognises abnormal behaviour, and agree how employees verify a request from "the IT department": through a known number or ticket, never through the link or number in the message itself.
3 · Do we keep sensitive data no longer than necessary?
What you do not store cannot leak. At Odido, identity document numbers had been sitting in the systems for years. Delete personal data in time; it limits risk, liability and the impact of an incident, and under the GDPR it is often mandatory.
4 · Is security structurally on the agenda?
Technology alone does not protect. Raise cybersecurity awareness regularly and train with realistic simulations, including phone-based social engineering. Awareness demonstrably lowers the risk.
Frequently asked questions
Do I have to do anything as an Odido customer?
No, but stay alert: the leaked data is used for phishing and identity fraud. Do not trust e-mails or calls "on behalf of Odido" and consider a new identity document if its number was leaked.
Does an SME have to report such an incident?
Yes, a data breach involving personal data must be reported to the Dutch Data Protection Authority within 72 hours and, if the risk is high, to the people affected. Under NIS2, designated organisations must also notify the NCSC within 24 hours.
What is the fastest measure with the biggest effect?
MFA on all accounts, starting with e-mail and administrator rights. It takes a day to set up and removes the most-used attack route.
Cybersecurity is a board matter: executive responsibility, not an IT project. Qteco helps organisations get the basics structurally and provably in order. Take the free Microsoft 365 security check as a starting point.
Sources
- Hack bij Odido, gegevens miljoenen klanten in handen van criminelen — NOS
- Datalek treft 6,2 miljoen Odido-klantenaccounts — Computable (2026-02-12)
Read also
Firewalls and VPNs under fire: how to keep the door shut
Ready to run worry-free?
Book a no-obligation introduction. We map your IT and security and show where the difference lies.
Book a call →
